page:guides:next js:private file access

Enforce private-file authorization for Next.js

Enforce private-file authorization in a Next.js app on Ample. The route handler authorizes the request first, records file metadata in a managed PostgreSQL database, stores bytes in a private bucket and streams them back only to authorized callers. The bucket is never published, so objects are reachable only through the app.

Representative Queries

Resource Requirements

Infrastructure Requirements

Workflow Steps

  1. Authorize before touching storage: Return 401 for unauthenticated requests; never expose object keys or the bucket endpoint to the browser.
  2. Record metadata in PostgreSQL: Keep the owner, name and object key in a table so authorization decisions come from your data, not from the bucket.
  3. Store and stream through the app: PutObject on upload, GetObject on download, both server-side with the injected credentials.
  4. Test both paths: An unauthenticated request must return 401; an authorized request must return the stored content.
  5. Verify: Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.

Tested Configuration

Prerequisites

Limitations

Cost Estimate

Success Checks

Examples

  1. Next.js private files canary: 401 without a token; private=ok with the token after a database write and a bucket round-trip.
    Source Ref: tests/deploy-canaries/next-private-files

Next Actions

Visit this link for more details in markdown format.